<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: In-shell PowerShell commands not captured in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/in-shell-powershell-commands-not-captured/m-p/426576#M962</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/150738"&gt;@BenHooper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It would seem that the endpoint is not collecting the logs necessary to report powershell activity to the Cortex Data Lake. If this issue persists, did you confirm if this device is attached to a policy that enables Enhanced data (&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/customizable-agent-settings/add-agent-settings-profile" target="_self"&gt;See step 10 of this link.&lt;/A&gt;)&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Aug 2021 17:08:05 GMT</pubDate>
    <dc:creator>gjenkins</dc:creator>
    <dc:date>2021-08-12T17:08:05Z</dc:date>
    <item>
      <title>In-shell PowerShell commands not captured</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/in-shell-powershell-commands-not-captured/m-p/351079#M329</link>
      <description>&lt;P&gt;As of at least 2020/07/10, I've only ever seen Cortex XDR capture PowerShell commands were included as parameters of a command-line process - never in-shell commands (opening PowerShell then manually executing the commands).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Enabling PowerShell module auditing / logging locally doesn't make a difference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this a known problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Examples below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020 ∕ 07 ∕ 10 15꞉05꞉16 - Rule_Builder_-_Cortex_XDR_-_Google_Chrome.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27837i9188B53F2A276CE1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2020 ∕ 07 ∕ 10 15꞉05꞉16 - Rule_Builder_-_Cortex_XDR_-_Google_Chrome.png" alt="2020 ∕ 07 ∕ 10 15꞉05꞉16 - Rule_Builder_-_Cortex_XDR_-_Google_Chrome.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020 ∕ 09 ∕ 22 15꞉38꞉24 - BIOC_-_Cortex_XDR_-_Google_Chrome.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27838i266F10D133D3ABE7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2020 ∕ 09 ∕ 22 15꞉38꞉24 - BIOC_-_Cortex_XDR_-_Google_Chrome.png" alt="2020 ∕ 09 ∕ 22 15꞉38꞉24 - BIOC_-_Cortex_XDR_-_Google_Chrome.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020 ∕ 09 ∕ 22 15꞉45꞉18 - Query_Results_-_Cortex_XDR_-_Google_Chrome.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27839iE791C96D7A448BD8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2020 ∕ 09 ∕ 22 15꞉45꞉18 - Query_Results_-_Cortex_XDR_-_Google_Chrome.png" alt="2020 ∕ 09 ∕ 22 15꞉45꞉18 - Query_Results_-_Cortex_XDR_-_Google_Chrome.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020 ∕ 09 ∕ 22 15꞉50꞉01 - Query_Results_-_Cortex_XDR_-_Google_Chrome.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27840iD91699AC5A512AEC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2020 ∕ 09 ∕ 22 15꞉50꞉01 - Query_Results_-_Cortex_XDR_-_Google_Chrome.png" alt="2020 ∕ 09 ∕ 22 15꞉50꞉01 - Query_Results_-_Cortex_XDR_-_Google_Chrome.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 14:55:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/in-shell-powershell-commands-not-captured/m-p/351079#M329</guid>
      <dc:creator>BenHooper</dc:creator>
      <dc:date>2020-09-22T14:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: In-shell PowerShell commands not captured</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/in-shell-powershell-commands-not-captured/m-p/426576#M962</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/150738"&gt;@BenHooper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It would seem that the endpoint is not collecting the logs necessary to report powershell activity to the Cortex Data Lake. If this issue persists, did you confirm if this device is attached to a policy that enables Enhanced data (&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/customizable-agent-settings/add-agent-settings-profile" target="_self"&gt;See step 10 of this link.&lt;/A&gt;)&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 17:08:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/in-shell-powershell-commands-not-captured/m-p/426576#M962</guid>
      <dc:creator>gjenkins</dc:creator>
      <dc:date>2021-08-12T17:08:05Z</dc:date>
    </item>
  </channel>
</rss>

